Get started

API keys and authentication

Every request carries an API key. Keys belong to a workspace and spend its balance; each can be held to its own budgets, models and addresses.

Sending the key

Either header works on every endpoint:

Headers
Authorization: Bearer zr_live_your_key_here
# or, as Anthropic's SDKs send it:
x-api-key: zr_live_your_key_here

Keys start with zr_live_. You see the full key once, when you create it; we only keep a hash, so nobody (us included) can show it to you again. Lost it? Revoke it and make another.

Keeping keys safe

  • Keep keys in a secret manager or environment variables, never in code or a repository.
  • Call zurelay from your server. A key in a browser or a mobile app can be read by anyone who has the app.
  • Use one key per app or environment (say, production and staging), so you can revoke one without touching the others.
  • Give each key only what it needs: a budget, the models it calls, the addresses it runs on. See Key limits and rules.
  • If a key leaks, revoke it under API keys. Requests with it stop within 15 seconds.

What a key can be held to

Monthly budgetUSD
Spend allowed per calendar month (UTC).
Daily budgetUSD
Spend allowed per day (UTC).
Rate limitrequests / minute
Requests per minute; more are refused with 429.
Expirydate
After it, the key stops working.
Allowed modelslist
Only these models; anything else is refused with 403.
Allowed IP addresseslist
Only requests from these addresses or ranges.
Smart routingsetting
What happens when a model is down: see Smart routing.

Authentication errors

StatusCodeMeans
401missing_api_keyNo key in the request.
401invalid_api_keyThe key doesn’t exist or was revoked.
401expired_api_keyThe key passed its expiry date.
403ip_not_allowedThe key only works from other addresses.
403model_not_allowedThe key isn’t allowed to use this model.
402insufficient_quotaThe workspace balance is empty.
Every chat, image and video response carries an x-request-id header. Include it when you write to support and we can find the request in seconds.

Questions, or something missing? Ask support in your dashboard or email support@zurelay.com.